Pith. sign in

REVIEW 5 major objections 5 minor 120 references

Privacy-Preserving Generative Models: A Comprehensive Survey

T0 review · 5 major / 5 minor · reviewed 2026-08-09 · deepseek-v4-flash

Pith's one-line read This survey maps the privacy and utility metrics used for GANs and VAEs into two novel taxonomies, based on 100 publications.

desk verdict A useful but uneven survey map: the taxonomy and coverage are genuinely helpful, while several metric formulas are wrong and the paper-selection method is undocumented. read the letter →

arxiv 2502.03668 v1 pith:O65GYWEE submitted 2025-02-05 cs.LG cs.CR

classification cs.LGcs.CR
keywords generativeadversarialnetworksvariationalautoencodersdifferentialprivacymembershipinferenceattacksmetricsutilitysyntheticdataprivacy-preservingmachinelearning
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This survey sets out to be the first systematic map of both privacy and utility metrics for generative models, specifically GANs and VAEs, built from an in-depth analysis of 100 research publications. It groups privacy attacks into four families and then arranges privacy and utility metrics into taxonomies, with the practical goal of letting a researcher choose evaluation measures knowingly. The paper argues that no earlier survey drew the same two-sided picture, and that this structure exposes gaps such as the absence of formal guarantees in attack-based metrics and the lack of a one-size-fits-all utility metric. If the map holds, it gives newcomers a shared vocabulary for comparing privacy-preserving generative models.

What carries the argument

The load-bearing device is the classification system itself: the attack taxonomy in Figure 1 divides privacy attacks by what they target, the privacy metric taxonomy in Figure 2 groups metrics into attack-based, generalization-based, and differential-privacy-based families, and the utility metric taxonomy in Figure 6 groups metrics into specific-task and fidelity families. Each metric gets a location in this tree and a set of neighbouring alternatives, which is what allows the survey to compare trade-offs and to spot missing categories.

What would settle it

Reproduce the selection process from the paper's stated scope and sources; if it does not converge on the same 100 papers, or if a systematically chosen set of additional papers on privacy-preserving diffusion models yields metrics that fit none of the taxonomy's categories, the survey's completeness claim fails.

Watch

Extended reading notes

Core claim

On the paper's own terms, the discovery is organizational rather than experimental: privacy and utility evaluation in generative models can be systematically categorized, and doing so reveals what existing measurements do and do not cover. The privacy side distinguishes four attack levels, namely training data, attribute, model, and identification-based, and three metric families: attack-based, generalization-based, and differential-privacy-based. The utility side distinguishes task-specific utility, covering classification, regression, and clustering, from fidelity, which is further split into distributional and individual-sample comparisons. The authors present these taxonomies as novel, based on 100 papers, and use them to compare the pros and cons of individual metrics and to identify open research challenges.

Load-bearing premise

The map's completeness rests on the undocumented selection of 100 papers from roughly 1200; if that selection is biased or incomplete, the taxonomies may miss important metrics or attacks even though individual descriptions may still be accurate.

Editorial extensions

If this is right

  • A newcomer can locate an attack or metric in the tree and immediately see which family it belongs to and what assumptions it carries.
  • Researchers can compare GAN- and VAE-based privacy results more fairly, since the taxonomy groups metrics by what they measure rather than by paper-specific names.
  • The identified trade-off between formal differential-privacy guarantees and practical attack-based measurement becomes a standard axis for evaluating synthetic data.
  • The utility taxonomy gives downstream users a checklist: classification, regression, and clustering metrics for task utility, plus distributional and individual distance metrics for fidelity.
  • The open-challenge discussion points to concrete next steps, such as robust distance-based privacy metrics and fairness metrics, for researchers entering the area.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The same two-sided taxonomy could plausibly be applied to synthetic data from diffusion models, but the model-level attack branch would likely need extension because diffusion models expose different components than GANs and VAEs.
  • The paper's comparison suggests a practical selection rule, namely use a differential-privacy metric when a formal guarantee is required, an attack-based metric when the adversary model is concrete, and a fidelity metric when downstream use is the goal; the authors do not explicitly state this rule.
  • A reproducible version of the selection process would let the taxonomy be updated as new attacks and metrics appear, turning it from a static survey into a living map.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

5 major / 5 minor

Summary. The paper surveys privacy and utility evaluation for generative models (GANs and VAEs). It proposes taxonomies for privacy attacks, privacy metrics, and utility metrics; reviews 100 publications; and discusses open challenges and future research directions. The central claims are that this is the first survey to systematically categorize privacy and utility perspectives of GANs and VAEs and that the proposed taxonomies provide a structured map for researchers selecting evaluation measures.

Significance. If corrected, this survey would be a useful reference: the taxonomies in Figures 2 and 6 and the data-type mapping in Table 2 organize a large body of work, and the metric-by-metric attributions are checkable against the cited literature. The paper does not ship code or machine-checked proofs, but it does provide a broad, manually curated coverage of 100 papers. The main value depends on the formal definitions being correct, because the stated purpose is to help researchers select and interpret privacy and utility metrics; several of the printed formulas are inconsistent with standard definitions and must be corrected before the reference value of the survey is reliable.

major comments (5)
  1. [§4.2.2, Eq. (26)] Eq. (26) defines PSNR = 10 log10(MSE/MAX^2), which is inverted with respect to the standard definition PSNR = 10 log10(MAX^2/MSE). For typical images with MSE < MAX^2, the printed formula returns negative values, reversing the semantics of the metric; since Section 5.2 and Table 2 recommend PSNR for image fidelity, a reader following the survey would misinterpret PSNR values. This equation should be corrected and the surrounding discussion updated.
  2. [§4.1.3, Eq. (7)] The silhouette score formula and its variable definitions are inconsistent with the standard definition. The standard silhouette score is (b-a)/max(a,b), with a the mean intra-cluster distance and b the mean nearest-cluster distance; Eq. (7) prints (a-b)/max(b,a) and then defines b as the within-cluster distance and a as a between-cluster distance. As printed, a reader using the standard notation would obtain the wrong sign, and the text's 'average distance between all clusters' is not the nearest-cluster distance used by the silhouette score. Please align the notation with the standard definition or state the swapped convention explicitly.
  3. [§4.1.2, Eq. (3)] The MAD metric in Eq. (3) is the median absolute deviation from the median of the target values, median(|y_i - median(y)|). This quantity does not compare actual target values with predicted values, despite the text's claim that MAD is a regression utility metric comparing synthetic predictions with real targets. If the intended quantity is the median absolute difference between y_i and y_i', the formula should involve both y_i and y_i'; as written it cannot serve the stated purpose.
  4. [§4.1.2, Eqs. (5)-(6)] Eq. (6) defines SStotal as (1/n) sum (y_i - y_i')^2, which is the mean squared error, not the total sum of squares of the observed data. In the standard R^2 formula, SStotal = sum (y_i - bar{y})^2, and the denominator in Eq. (5) must be the total variance of the target variable. As printed, Eqs. (5) and (6) do not define R^2 and would mislead a reader computing goodness of fit for synthetic data.
  5. [§5] The paper's comprehensiveness claim is not supported by a documented selection process: Section 5 states that 'Starting with approximately 1200 papers, we identified 100 research publications for in-depth analysis,' but the survey provides no search strategy, database sources, inclusion/exclusion criteria, screening steps, or inter-rater procedure. Without this information, the 'first comprehensive survey' claim and the completeness of the taxonomies in Figures 2 and 6 cannot be assessed. Please add a methodology subsection or temper the claims accordingly.
minor comments (5)
  1. [§4.1.3] The text says 'The range of CCS is −1 to 1' but the acronym is CSS; the term 'clustering silhouette score' should be defined before Eq. (7) is used.
  2. [§4.2.1, Eqs. (21)-(22)] Eq. (22) uses the undefined symbol 'xbar' in the displayed formula; replace it with bar{x} or define it in the notation list.
  3. [§4.2.2, Eq. (27)] 'Frobennius norm' should be 'Frobenius norm'.
  4. [§4.1.2, Eq. (4)] Eq. (4) sums from i=0 to n-1 while the other regression equations sum from i=1 to n; the indexing should be made consistent.
  5. [§3.1.1] The description of the true acceptance rate (TAR) as 'the ratio of true positive identifications to false positive identifications' is not the standard definition; TAR is normally the true positive rate. Please correct or qualify this description.

Circularity Check

0 steps flagged · score 1.0 of 10

No significant circularity; a single minor non-load-bearing self-citation does not affect the survey's taxonomy content.

full rationale

This paper is a survey: it organizes privacy attacks, privacy metrics, and utility metrics drawn from 100 cited publications into taxonomies. It does not fit parameters and then relabel them as predictions, nor does it define any derived quantity in terms of its own conclusions. The only identifiable self-citation is reference [101], a prior systematic survey co-authored by Isabel Wagner, cited in Section 5.1 for the advisory statement that 'Selecting privacy metrics that reflect both the average and worst case is often recommended [101].' That citation supports a general recommendation and is not load-bearing for the central claim of the paper, which is the completeness and categorization of the surveyed metrics. The claimed 'first work' status rests on an undocumented paper-selection process, but that is a methodology/completeness concern, not circularity. The incorrect metric equations identified by the skeptical reader (e.g., Eq. 26 inverting PSNR, Eq. 3 giving median absolute deviation from the median, Eq. 7 swapping the silhouette-score sign) are correctness defects in the survey's reporting, not instances of a derivation reducing to its inputs. They do not make the survey circular; they make portions of it inaccurate. Accordingly, the appropriate circularity finding is low: score 1 reflects only the minor, non-load-bearing self-citation, with no circular step to report.

Assumptions & free parameters 0 free parameters · 4 assumptions · 0 invented entities

No free parameters, no invented entities. The central load depends on the undocumented selection of 100 papers and on accurate re-description of others' metrics, which is partially violated (PSNR, silhouette, MAD equations).

assumptions (4)
  • domain assumption The selected 100 publications are representative of the field
    The survey's comprehensiveness and taxonomies rely on the paper selection described only as 'Starting with approximately 1200 papers, we identified 100 research publications for in-depth analysis' (Section 5). No search protocol or inclusion/exclusion criteria are given.
  • domain assumption GANs and VAEs are the relevant generative model classes for privacy-preserving synthetic data
    Section 1.2 explicitly narrows scope to GANs and VAEs, excluding transformer-based and statistical models, so the claimed gap for 'privacy-preserving generative models' is scoped by this choice.
  • domain assumption The metric definitions from the cited papers are correctly understood
    The survey re-states equations for metrics such as PSNR and silhouette score; errors indicate this assumption is partially violated.
  • standard math Standard definitions of divergence and distance metrics from probability theory
    Equations for KL, JSD, Wasserstein, and related metrics rely on standard math facts; these are not invented for this paper.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Privacy-Preserving Generative Models: A Comprehensive Survey." pith.science (2026). https://pith.science/paper/O65GYWEE

@misc{pith2026250203668,
  author       = {Pith},
  title        = {Pith review of: Privacy-Preserving Generative Models: A Comprehensive Survey},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/O65GYWEE}},
  note         = {Machine review of arXiv:2502.03668}
}
read the original abstract

Despite the generative model's groundbreaking success, the need to study its implications for privacy and utility becomes more urgent. Although many studies have demonstrated the privacy threats brought by GANs, no existing survey has systematically categorized the privacy and utility perspectives of GANs and VAEs. In this article, we comprehensively study privacy-preserving generative models, articulating the novel taxonomies for both privacy and utility metrics by analyzing 100 research publications. Finally, we discuss the current challenges and future research directions that help new researchers gain insight into the underlying concepts.

Figures

Figures reproduced from arXiv: 2502.03668 by the authors.

Figure 1
Figure 1. Types of Privacy Attacks in Generative Models [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. Taxonomy of Privacy Metrics in Generative Models [PITH_FULL_IMAGE:figures/full_fig_p006_2.png] view at source ↗
Figure 3
Figure 3. Noise Addition strategies in GANs improving optimization strategies, which helps reduce privacy budget consumption. Hence, we have classified the noise perturbation strategies into four categories: noise addition to the discriminator’s gradient in GANs, noise addition to the discriminator’s output or loss function in GANs, noise addition techniques in VAEs, and noise addition to the latent vector in generative model… view at source ↗
Figures from the paper (4 more)
Figure 4
Figure 4. Figure 4: Noise Addition Strategies in VAEs training performance. This study focuses on efficient differential private GANs by adding noise to the discriminator’s output or loss function. The idea is that by adding noise to the discriminator’s loss function, the generator become…
Figure 5
Figure 5. Figure 5: Noise Addition Techniques in GANs by PATE Mechanism [55] [PITH_FULL_IMAGE:figures/full_fig_p011_5.png]
Figure 6
Figure 6. Figure 6: Taxonomy of Utility Metrics in Generative Models [PITH_FULL_IMAGE:figures/full_fig_p012_6.png]
Figure 7
Figure 7. Figure 7: Evaluation Workflow of GAN-based Synthetic Data on Regression Tasks [PITH_FULL_IMAGE:figures/full_fig_p013_7.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

120 extracted references · 73 canonical work pages

  1. [1]

    Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang

    Martin Abadi, Andy Chu, Ian Goodfellow, H. Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. Deep Learning with Differential Privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pages 308–318, Vienna Austria, October 2016. ACM

  2. [2]

    Counterfactual Fairness in Synthetic Data Generation

    Mahed Abroshan, Mohammad Mahdi Khalili, and Andrew Elliott. Counterfactual Fairness in Synthetic Data Generation. In NeurIPS 2022 Workshop on Synthetic Data for Empowering ML Research, New Orleans, U.S, October 2022. 23

  3. [3]

    Differentially Private Mixture of Generative Neural Networks

    Gergely Acs, Luca Melis, Claude Castelluccia, and Emiliano De Cristofaro. Differentially Private Mixture of Generative Neural Networks. In 2017 IEEE International Conference on Data Mining (ICDM), pages 715–720, New Orleans, LA, November 2017. IEEE

  4. [4]

    Generalization in Transfer Learning

    Suzan Ece Ada, Emre Ugur, and H. Levent Akin. Generalization in Transfer Learning. Robotica, 40(11):3811– 3836, November 2022. arXiv:1909.01331 [cs, stat]

  5. [5]

    Differential privacy synthetic data generation using WGANs, 2019

    Moustafa Alzantot and Mani Srivastava. Differential privacy synthetic data generation using WGANs, 2019. original-date: 2019-05-29T04:58:58Z

  6. [6]

    Wasserstein Generative Adversarial Networks

    Martin Arjovsky, Soumith Chintala, and Léon Bottou. Wasserstein Generative Adversarial Networks. In Proceedings of the 34th International Conference on Machine Learning, pages 214–223, Sydney, Australia, July

  7. [7]

    Scott Armstrong and Fred Collopy

    J. Scott Armstrong and Fred Collopy. Error measures for generalizing about forecasting methods: Empirical comparisons. International Journal of Forecasting, 8(1):69–80, June 1992

  8. [8]

    A White-Box Generator Membership Inference Attack Against Generative Models

    Maryam Azadmanesh, Behrouz Shahgholi Ghahfarokhi, and Maede Ashouri Talouki. A White-Box Generator Membership Inference Attack Against Generative Models. In 2021 18th International ISC Conference on Information Security and Cryptology (ISCISC), pages 13–17, Iran, September 2021. IEEE (Institute of Electrical and Electronics Engineers. ISSN: 2475-2371

Show all 120 references
  1. [9]

    Differential Privacy Has Disparate Impact on Model Accuracy

    Eugene Bagdasaryan, Omid Poursaeed, and Vitaly Shmatikov. Differential Privacy Has Disparate Impact on Model Accuracy. In Advances in Neural Information Processing Systems, volume 32, Vancouver, Canada, 2019. Curran Associates, Inc

  2. [10]

    Beaulieu-Jones, Zhiwei Steven Wu, Chris Williams, Ran Lee, Sanjeev P

    Brett K. Beaulieu-Jones, Zhiwei Steven Wu, Chris Williams, Ran Lee, Sanjeev P. Bhavnani, James Brian Byrd, and Casey S. Greene. Privacy-preserving generative deep neural networks support clinical data sharing.American Heart Association, 12(7):e005122, 2019

  3. [11]

    Privacy and synthetic datasets

    Steven M Bellovin, Preetam K Dutta, and Nathan Reitinger. Privacy and synthetic datasets. Stan. Tech. L. Rev., 22:1, 2019

  4. [12]

    Assessing Differentially Private Variational Autoencoders Under Membership Inference

    Daniel Bernau, Jonas Robl, and Florian Kerschbaum. Assessing Differentially Private Variational Autoencoders Under Membership Inference. In Shamik Sural and Haibing Lu, editors, Data and Applications Security and Privacy XXXVI, Lecture Notes in Computer Science, pages 3–14, Ch...

  5. [13]

    Private GANs, Revisited

    Alex Bie, Gautam Kamath, and Guojun Zhang. Private GANs, Revisited. Transactions on Machine Learning Research, February 2023

  6. [14]

    SupMMD: A Sentence Importance Model for Extractive Summarization using Maximum Mean Discrepancy

    Umanga Bista, Alexander Mathews, Aditya Menon, and Lexing Xie. SupMMD: A Sentence Importance Model for Extractive Summarization using Maximum Mean Discrepancy. In Trevor Cohn, Yulan He, and Yang Liu, editors, Findings of the Association for Computational Linguistics: EMNLP 202...

  7. [15]

    Generative Adversarial Networks: A Survey Toward Private and Secure Applications

    Zhipeng Cai, Zuobin Xiong, Honghui Xu, Peng Wang, Wei Li, and Yi Pan. Generative Adversarial Networks: A Survey Toward Private and Secure Applications. ACM Computing Surveys, 54(6):132:1–132:38, July 2021

  8. [16]

    GS-WGAN: a gradient-sanitized approach for learning differentially private generators

    Dingfan Chen, Tribhuvanesh Orekondy, and Mario Fritz. GS-WGAN: a gradient-sanitized approach for learning differentially private generators. In Proceedings of the 34th International Conference on Neural Information Processing Systems, NIPS’20, pages 12673–12684, Red Hook, NY ,...

  9. [17]

    GAN-Leaks: A Taxonomy of Membership Inference Attacks against Generative Models

    Dingfan Chen, Ning Yu, Yang Zhang, and Mario Fritz. GAN-Leaks: A Taxonomy of Membership Inference Attacks against Generative Models. In Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, pages 343–362, Virtual Event USA, October 2020. ACM

  10. [18]

    Differentially Private Generative Adversarial Networks with Model Inversion

    Dongjie Chen, Sen-ching Samson Cheung, Chen-Nee Chuah, and Sally Ozonoff. Differentially Private Generative Adversarial Networks with Model Inversion. In 2021 IEEE International Workshop on Information Forensics and Security (WIFS), pages 1–6, Montpellier, France, December 202...

  11. [19]

    Generating a trading strategy in the financial market from sensitive expert data based on the privacy-preserving generative adversarial imitation network

    Hsin-Yi Chen and Szu-Hao Huang. Generating a trading strategy in the financial market from sensitive expert data based on the privacy-preserving generative adversarial imitation network. Neurocomputing, 500:616–631, August 2022

  12. [20]

    VGAN-Based Image Representation Learning for Privacy- Preserving Facial Expression Recognition

    Jiawei Chen, Janusz Konrad, and Prakash Ishwar. VGAN-Based Image Representation Learning for Privacy- Preserving Facial Expression Recognition. In 2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), pages 1651–165109, Salt Lake City, UT, USA,...

  13. [21]

    PAR-GAN: Improving the Generalization of Generative Adversarial Networks Against Membership Inference Attacks

    Junjie Chen, Wendy Hui Wang, Hongchang Gao, and Xinghua Shi. PAR-GAN: Improving the Generalization of Generative Adversarial Networks Against Membership Inference Attacks. In Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery & Data Mining, pages 127–137, Vir...

  14. [22]

    Tianwei Chen, Yusuke Hirota, Mayu Otani, Noa Garcia, and Yuta Nakashima. Would Deep Generative Models Amplify Bias in Future Models? In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 10833–10843, Seattle Convention Center, 2024. IEEE

  15. [23]

    Suriyakumar, Natalie Dullerud, Shalmali Joshi, and Marzyeh Ghassemi

    Victoria Cheng, Vinith M. Suriyakumar, Natalie Dullerud, Shalmali Joshi, and Marzyeh Ghassemi. Can You Fake It Until You Make It?: Impacts of Differentially Private Synthetic Data on Downstream Classification Fairness. In Proceedings of the 2021 ACM Conference on Fairness, Acc...

  16. [24]

    Generating multi-label discrete patient records using generative adversarial networks

    Edward Choi, Siddharth Biswal, Bradley Malin, Jon Duke, Walter F Stewart, and Jimeng Sun. Generating multi-label discrete patient records using generative adversarial networks. In Machine learning for healthcare conference, pages 286–305, Boston, Massachusetts, USA, 2017. PMLR, PMLR

  17. [25]

    Croft, Jörg-Rüdiger Sack, and Wei Shi

    William L. Croft, Jörg-Rüdiger Sack, and Wei Shi. Differentially private facial obfuscation via generative adversarial networks. Future Generation Computer Systems, 129:358–379, April 2022

  18. [26]

    ArcFace: Additive Angular Margin Loss for Deep Face Recognition

    Jiankang Deng, Jia Guo, Niannan Xue, and Stefanos Zafeiriou. ArcFace: Additive Angular Margin Loss for Deep Face Recognition. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 4690–4699, California, USA, 2019. IEEE

  19. [27]

    A cosine similarity-based negative selection algorithm for time series novelty detection

    Yonggui Dong, Zhaoyan Sun, and Huibo Jia. A cosine similarity-based negative selection algorithm for time series novelty detection. Mechanical Systems and Signal Processing, 20(6):1461–1472, August 2006

  20. [28]

    Identifying and handling data bias within primary healthcare data using synthetic data generators

    Barbara Draghi, Zhenchen Wang, Puja Myles, and Allan Tucker. Identifying and handling data bias within primary healthcare data using synthetic data generators. Heliyon, 10(2):e24164, January 2024

  21. [29]

    Differential Privacy: A Survey of Results

    Cynthia Dwork. Differential Privacy: A Survey of Results. In Manindra Agrawal, Dingzhu Du, Zhenhua Duan, and Angsheng Li, editors, Theory and Applications of Models of Computation , Lecture Notes in Computer Science, pages 1–19, Berlin, Heidelberg, 2008. Springer

  22. [30]

    A survey of differentially private generative adversarial networks

    Liyue Fan. A survey of differentially private generative adversarial networks. In The AAAI Workshop on Privacy-Preserving Artificial Intelligence, page 8, New York, USA, 2020

  23. [31]

    T. Foss, E. Stensrud, B. Kitchenham, and I. Myrtveit. A simulation study of the model evaluation criterion MMRE. IEEE Transactions on Software Engineering, 29(11):985–995, November 2003

  24. [32]

    Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures

    Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, CCS ’15, pages 1322–1333, New York, NY , USA, Oc...

  25. [33]

    Differentially Private Generative Adversarial Networks for Time Series, Continuous, and Discrete Open Data

    Lorenzo Frigerio, Anderson Santana de Oliveira, Laurent Gomez, and Patrick Duverger. Differentially Private Generative Adversarial Networks for Time Series, Continuous, and Discrete Open Data. In Gurpreet Dhillon, Fredrik Karlsson, Karin Hedström, and André Zúquete, editors, I...

  26. [34]

    Live Face De-Identification in Video

    Oran Gafni, Lior Wolf, and Yaniv Taigman. Live Face De-Identification in Video. In Proceedings of the IEEE/CVF International Conference on Computer Vision, pages 9378–9387, Seattle, Washington, USA, 2019. IEEE

  27. [35]

    DP-SGD vs PATE: Which Has Less Disparate Impact on GANs?, November 2021

    Georgi Ganev. DP-SGD vs PATE: Which Has Less Disparate Impact on GANs?, November 2021

  28. [36]

    Robin Hood and Matthew Effects: Differential Privacy Has Disparate Impact on Synthetic Data

    Georgi Ganev, Bristena Oprisanu, and Emiliano De Cristofaro. Robin Hood and Matthew Effects: Differential Privacy Has Disparate Impact on Synthetic Data. In Proceedings of the 39th International Conference on Machine Learning, pages 6944–6959, Baltimore, Maryland, USA, June 2022. PMLR

  29. [37]

    Graphical vs

    Georgi Ganev, Kai Xu, and Emiliano De Cristofaro. Graphical vs. Deep Generative Models: Measuring the Impact of Differentially Private Mechanisms and Budgets on Utility, May 2023

  30. [38]

    A Unified Framework for Quantifying Privacy Risk in Synthetic Data

    Matteo Giomi, Franziska Boenisch, Christoph Wehmeyer, and Borbála Tasnádi. A Unified Framework for Quantifying Privacy Risk in Synthetic Data. Proceedings on Privacy Enhancing Technologies, 2023:312–328, 2023

  31. [39]

    Generation and evaluation of synthetic patient data

    Andre Goncalves, Priyadip Ray, Braden Soper, Jennifer Stevens, Linda Coyle, and Ana Paula Sales. Generation and evaluation of synthetic patient data. BMC Medical Research Methodology, 20(1):108, May 2020. 25

  32. [40]

    Generative adversarial networks

    Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio. Generative adversarial networks. Communications of the ACM, 63(11):139–144, October 2020

  33. [41]

    Improved training of wasserstein gans

    Ishaan Gulrajani, Faruk Ahmed, Martin Arjovsky, Vincent Dumoulin, and Aaron C Courville. Improved training of wasserstein gans. Advances in neural information processing systems, 30, 2017

  34. [42]

    Utility-Aware Synthesis of Differentially Private and Attack-Resilient Location Traces

    Mehmet Emre Gursoy, Ling Liu, Stacey Truex, Lei Yu, and Wenqi Wei. Utility-Aware Synthesis of Differentially Private and Attack-Resilient Location Traces. InProceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, pages 196–211, Toronto Canada, Oc...

  35. [43]

    Differentially private GANs by adding noise to Discriminator’s loss

    Chunling Han and Rui Xue. Differentially private GANs by adding noise to Discriminator’s loss. Computers & Security, 107:102322, August 2021

  36. [44]

    LOGAN: Membership Inference Attacks Against Generative Models

    Jamie Hayes, Luca Melis, George Danezis, and Emiliano De Cristofaro. LOGAN: Membership Inference Attacks Against Generative Models. Proceedings on Privacy Enhancing Technologies, 2019(1):133–152, January 2019

  37. [45]

    GANs Trained by a Two Time-Scale Update Rule Converge to a Local Nash Equilibrium, January 2018

    Martin Heusel, Hubert Ramsauer, Thomas Unterthiner, Bernhard Nessler, and Sepp Hochreiter. GANs Trained by a Two Time-Scale Update Rule Converge to a Local Nash Equilibrium, January 2018. arXiv:1706.08500 [cs, stat]

  38. [46]

    Monte carlo and reconstruction membership inference attacks against generative models

    Benjamin Hilprecht, Martin Härterich, and Daniel Bernau. Monte carlo and reconstruction membership inference attacks against generative models. Proc. Priv. Enhancing Technol., 2019(4):232–249, 2019

  39. [47]

    DP-GAN: Differentially private consecutive data publishing using generative adversarial nets

    Stella Ho, Youyang Qu, Bruce Gu, Longxiang Gao, Jianxin Li, and Yong Xiang. DP-GAN: Differentially private consecutive data publishing using generative adversarial nets. Journal of Network and Computer Applications, 185:103066, July 2021

  40. [48]

    Cohen, Owen Daniel, Andrew Elliott, James Geddes, Callum Mole, Camila Rangel-Smith, and Lukasz Szpruch

    Florimond Houssiau, James Jordon, Samuel N. Cohen, Owen Daniel, Andrew Elliott, James Geddes, Callum Mole, Camila Rangel-Smith, and Lukasz Szpruch. TAPAS: a Toolbox for Adversarial Privacy Auditing of Synthetic Data. In NeurIPS 2022 Workshop on Synthetic Data for Empowering ML...

  41. [49]

    TableGAN-MCA: Evaluating Membership Collisions of GAN-Synthesized Tabular Data Releasing

    Aoting Hu, Renjie Xie, Zhigang Lu, Aiqun Hu, and Minhui Xue. TableGAN-MCA: Evaluating Membership Collisions of GAN-Synthesized Tabular Data Releasing. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, CCS ’21, pages 2096–2112, New York, ...

  42. [50]

    Model Extraction and Defenses on Generative Adversarial Networks, January 2021

    Hailong Hu and Jun Pang. Model Extraction and Defenses on Generative Adversarial Networks, January 2021

  43. [51]

    An Empirical Study on the Membership Inference Attack against Tabular Data Synthesis Models

    Jihyeon Hyeong, Jayoung Kim, Noseong Park, and Sushil Jajodia. An Empirical Study on the Membership Inference Attack against Tabular Data Synthesis Models. In Proceedings of the 31st ACM International Conference on Information & Knowledge Management, CIKM ’22, pages 4064–4068,...

  44. [52]

    Synthetic and Private Smart Health Care Data Generation using GANs

    Sana Imtiaz, Muhammad Arsalan, Vladimir Vlassov, and Ramin Sadre. Synthetic and Private Smart Health Care Data Generation using GANs. In 2021 International Conference on Computer Communications and Networks (ICCCN), pages 1–7, Athens, Greece, July 2021. IEEE

  45. [53]

    DP$^2$-V AE: Differentially Private Pre-trained Variational Autoencoders, August 2022

    Dihong Jiang, Guojun Zhang, Mahdi Karami, Xi Chen, Yunfeng Shao, and Yaoliang Yu. DP$^2$-V AE: Differentially Private Pre-trained Variational Autoencoders, August 2022

  46. [54]

    Pruning’s Effect on Generalization Through the Lens of Training and Regularization

    Tian Jin, Michael Carbin, Dan Roy, Jonathan Frankle, and Gintare Karolina Dziugaite. Pruning’s Effect on Generalization Through the Lens of Training and Regularization. Advances in Neural Information Processing Systems, 35:37947–37961, December 2022

  47. [55]

    PATE-GAN: Generating Synthetic Data with Differential Privacy Guarantees

    James Jordon, Jinsung Yoon, and Mihaela van der Schaar. PATE-GAN: Generating Synthetic Data with Differential Privacy Guarantees. In ICLR 2019, New Orleans, LA, USA, February 2022

  48. [56]

    Progressive Growing of GANs for Improved Quality, Stability, and Variation, February 2018

    Tero Karras, Timo Aila, Samuli Laine, and Jaakko Lehtinen. Progressive Growing of GANs for Improved Quality, Stability, and Variation, February 2018. arXiv:1710.10196 [cs, stat]

  49. [57]

    A style-based generator architecture for generative adversarial networks

    Tero Karras, Samuli Laine, and Timo Aila. A style-based generator architecture for generative adversarial networks. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition , pages 4401–4410, California, USA, 2019. IEEE

  50. [58]

    OCT-GAN: Neural ODE-based Conditional Tabular GANs

    Jayoung Kim, Jinsung Jeon, Jaehoon Lee, Jihyeon Hyeong, and Noseong Park. OCT-GAN: Neural ODE-based Conditional Tabular GANs. In Proceedings of the Web Conference 2021, WWW ’21, pages 1506–1515, New York, NY , USA, June 2021. Association for Computing Machinery

  51. [59]

    Stochastic gradient vb and the variational auto-encoder

    Diederik P Kingma and Max Welling. Stochastic gradient vb and the variational auto-encoder. In Second International Conference on Learning Representations, ICLR, volume 19, page 121, Alberta, Canada, 2014. 26

  52. [60]

    PriveTAB: Secure and Privacy- Preserving sharing of Tabular Data

    Anantaa Kotal, Aritran Piplai, Sai Sree Laya Chukkapalli, and Anupam Joshi. PriveTAB: Secure and Privacy- Preserving sharing of Tabular Data. In Proceedings of the 2022 ACM on International Workshop on Security and Privacy Analytics, IWSPA ’22, pages 35–45, New York, NY , USA,...

  53. [61]

    Unnoticeable synthetic face replacement for image privacy protection

    Zhenzhong Kuang, Zhiqiang Guo, Jinglong Fang, Jun Yu, Noboru Babaguchi, and Jianping Fan. Unnoticeable synthetic face replacement for image privacy protection. Neurocomputing, 457:322–333, October 2021

  54. [62]

    DTGAN: Differential Private Training for Tabular GANs, July 2021

    Aditya Kunar, Robert Birke, Zilong Zhao, and Lydia Chen. DTGAN: Differential Private Training for Tabular GANs, July 2021

  55. [63]

    Invertible Tabular GANs: Killing Two Birds with One Stone for Tabular Data Synthesis

    JAEHOON LEE, Jihyeon Hyeong, Jinsung Jeon, Noseong Park, and Jihoon Cho. Invertible Tabular GANs: Killing Two Birds with One Stone for Tabular Data Synthesis. In Advances in Neural Information Processing Systems, volume 34, pages 4263–4273, online, 2021. Curran Associates, Inc

  56. [64]

    Detecting outliers: Do not use standard deviation around the mean, use absolute deviation around the median

    Christophe Leys, Christophe Ley, Olivier Klein, Philippe Bernard, and Laurent Licata. Detecting outliers: Do not use standard deviation around the mean, use absolute deviation around the median. Journal of Experimental Social Psychology, 49(4):764–766, July 2013

  57. [65]

    Assessing the accuracy of predictive models for numerical data: Not r nor r2, why not? Then what? PLOS ONE, 12(8):e0183250, August 2017

    Jin Li. Assessing the accuracy of predictive models for numerical data: Not r nor r2, why not? Then what? PLOS ONE, 12(8):e0183250, August 2017

  58. [66]

    Privacy-preserving lightweight face recognition.Neurocomputing, 363(C):212–222, October 2019

    Yuancheng Li, Yimeng Wang, and Daoxing Li. Privacy-preserving lightweight face recognition.Neurocomputing, 363(C):212–222, October 2019

  59. [67]

    Subverting Privacy-Preserving GANs: Hiding Secrets in Sanitized Images

    Kang Liu, Benjamin Tan, and Siddharth Garg. Subverting Privacy-Preserving GANs: Hiding Secrets in Sanitized Images. Proceedings of the AAAI Conference on Artificial Intelligence, 35(17):14849–14856, May 2021

  60. [68]

    Performing Co-membership Attacks Against Deep Generative Models

    Kin Sum Liu, Chaowei Xiao, Bo Li, and Jie Gao. Performing Co-membership Attacks Against Deep Generative Models. In 2019 IEEE International Conference on Data Mining (ICDM) , pages 459–467, Beijing, China, November 2019. IEEE

  61. [69]

    Yu, and Yi Wu

    Yi Liu, Jialiang Peng, James J.Q. Yu, and Yi Wu. PPGAN: Privacy-Preserving Generative Adversarial Network. In 2019 IEEE 25th International Conference on Parallel and Distributed Systems (ICPADS), pages 985–989, Tianjin, China, December 2019. IEEE

  62. [70]

    G-PATE: Scalable Differentially Private Data Generator via Private Aggregation of Teacher Discriminators

    Yunhui Long, Boxin Wang, Zhuolin Yang, Bhavya Kailkhura, Aston Zhang, Carl Gunter, and Bo Li. G-PATE: Scalable Differentially Private Data Generator via Private Aggregation of Teacher Discriminators. In Advances in Neural Information Processing Systems, volume 34, pages 2965–2...

  63. [71]

    POSTER: A Unified Framework of Differentially Private Synthetic Data Release with Generative Adversarial Network

    Pei-Hsuan Lu and Chia-Mu Yu. POSTER: A Unified Framework of Differentially Private Synthetic Data Release with Generative Adversarial Network. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pages 2547–2549, Dallas Texas USA, October 2017. ACM

  64. [72]

    Machine Learning for Synthetic Data Generation: A Review, May 2024

    Yingzhou Lu, Minjie Shen, Huazheng Wang, Xiao Wang, Capucine van Rechem, Tianfan Fu, and Wenqi Wei. Machine Learning for Synthetic Data Generation: A Review, May 2024. arXiv:2302.04062 [cs]

  65. [73]

    Vincent Poor

    Chuan Ma, Jun Li, Ming Ding, Bo Liu, Kang Wei, Jian Weng, and H. Vincent Poor. RDP-GAN: A rényi- differential privacy based generative adversarial network. IEEE Transactions on Dependable and Secure Computing, 20(6):1–15, 2023. Conference Name: IEEE Transactions on Dependable ...

  66. [74]

    CIAGAN: Conditional Identity Anonymization Generative Adversarial Networks

    Maxim Maximov, Ismail Elezi, and Laura Leal-Taixé. CIAGAN: Conditional Identity Anonymization Generative Adversarial Networks. In 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pages 5446–5455, Seattle, Washington, USA, June 2020. IEEE. ISSN: 2575-7075

  67. [75]

    Anonymizing Speech with Generative Adversarial Networks to Preserve Speaker Privacy

    Sarina Meyer, Pascal Tilli, Pavel Denisov, Florian Lux, Julia Koch, and Ngoc Thang Vu. Anonymizing Speech with Generative Adversarial Networks to Preserve Speaker Privacy. In 2022 IEEE Spoken Language Technology Workshop (SLT), pages 912–919, Doha, Qatar, January 2023. IEEE

  68. [76]

    A Probe Towards Understanding GAN and V AE Models, December

    Lu Mi, Macheng Shen, and Jingzhao Zhang. A Probe Towards Understanding GAN and V AE Models, December

  69. [77]

    Rényi Differential Privacy

    Ilya Mironov. Rényi Differential Privacy. In 2017 IEEE 30th Computer Security Foundations Symposium (CSF), pages 263–275, California, USA, August 2017. IEEE. ISSN: 2374-8303

  70. [78]

    Conditional Generative Adversarial Nets, November 2014

    Mehdi Mirza and Simon Osindero. Conditional Generative Adversarial Nets, November 2014. arXiv:1411.1784 [cs, stat]

  71. [79]

    Spectral Normalization for Generative Adversarial Networks

    Takeru Miyato, Toshiki Kataoka, Masanori Koyama, and Yuichi Yoshida. Spectral Normalization for Generative Adversarial Networks. In Sixth International Conference on Learning Representations, ICLR , Vancouver Convention Centre, Vancouver, Canada, February 2018. 27

  72. [80]

    Helena Montenegro, Wilson Silva, and Jaime S. Cardoso. Privacy-Preserving Generative Adversarial Network for Case-Based Explainability in Medical Image Analysis. IEEE Access, 9:148037–148047, 2021

  73. [81]

    DPD-InfoGAN: Differentially Private Distributed InfoGAN

    Vaikkunth Mugunthan, Vignesh Gokul, Lalana Kagal, and Shlomo Dubnov. DPD-InfoGAN: Differentially Private Distributed InfoGAN. In Proceedings of the 1st Workshop on Machine Learning and Systems, pages 1–6, Online United Kingdom, April 2021. ACM

  74. [82]

    Sumit Mukherjee, Yixi Xu, Anusua Trivedi, Nabajyoti Patowary, and Juan L. Ferres. privGAN: Protecting GANs from membership inference attacks at low cost to utility. Proceedings on Privacy Enhancing Technologies, 2021(3):142–163, July 2021

  75. [83]

    Automatic detection of outliers and the number of clusters in k-means clustering via Chebyshev-type inequalities

    Peter Olukanmi, Fulufhelo Nelwamondo, Tshilidzi Marwala, and Bhekisipho Twala. Automatic detection of outliers and the number of clusters in k-means clustering via Chebyshev-type inequalities. Neural Computing and Applications, 34(8):5939–5958, April 2022

  76. [84]

    On Utility and Privacy in Synthetic Genomic Data

    Bristena Oprisanu, Georgi Ganev, and Emiliano De Cristofaro. On Utility and Privacy in Synthetic Genomic Data. In Proceedings 2022 Network and Distributed System Security Symposium, San Diego, CA, USA, April

  77. [85]

    Privacy-enhanced generative adversarial network with adaptive noise allocation

    Ke Pan, Maoguo Gong, and Yuan Gao. Privacy-enhanced generative adversarial network with adaptive noise allocation. Knowledge-Based Systems, 272:110576, July 2023

  78. [86]

    Scalable Private Learning with PATE

    Nicolas Papernot, Shuang Song, Ilya Mironov, Ananth Raghunathan, Kunal Talwar, and Ulfar Erlingsson. Scalable Private Learning with PATE. In The Sixth International Conference on Learning Representations , Vancouver, British Columbia, Canada, February 2018

  79. [87]

    Evaluating Differentially Private Generative Adversarial Networks Over Membership Inference Attack

    Cheolhee Park, Youngsoo Kim, Jong-Geun Park, Dowon Hong, and Changho Seo. Evaluating Differentially Private Generative Adversarial Networks Over Membership Inference Attack. IEEE Access, 9:167412–167425, 2021

  80. [88]

    Data synthesis based on generative adversarial networks

    Noseong Park, Mahmoud Mohammadi, Kshitij Gorde, Sushil Jajodia, Hongkyu Park, and Youngmin Kim. Data synthesis based on generative adversarial networks. Proceedings of the VLDB Endowment, 11(10):1071–1083, June 2018

  81. [89]

    Unsupervised representation learning with deep convolutional generative adversarial networks, 2016

    Alec Radford, Luke Metz, and Soumith Chintala. Unsupervised representation learning with deep convolutional generative adversarial networks, 2016

  82. [90]

    Improved Techniques for Training GANs

    Tim Salimans, Ian Goodfellow, Wojciech Zaremba, Vicki Cheung, Alec Radford, Xi Chen, and Xi Chen. Improved Techniques for Training GANs. In Advances in Neural Information Processing Systems, volume 29, Barcelona, Spain, 2016. Curran Associates, Inc

  83. [91]

    Differentially-Private Text Generation via Text Preprocessing to Reduce Utility Loss

    Taisho Sasada, Masataka Kawai, Yuzo Taenaka, Doudou Fall, and Youki Kadobayashi. Differentially-Private Text Generation via Text Preprocessing to Reduce Utility Loss. In 2021 International Conference on Artificial Intelligence in Information and Communication (ICAIIC), pages 0...

  84. [92]

    FaceNet: A unified embedding for face recognition and clustering

    Florian Schroff, Dmitry Kalenichenko, and James Philbin. FaceNet: A unified embedding for face recognition and clustering. pages 815–823, June 2015

  85. [93]

    Membership inference attacks against machine learning models

    Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. Membership inference attacks against machine learning models. In 2017 IEEE symposium on security and privacy (SP), pages 3–18, California, USA,

  86. [94]

    Synthetic Data – Anonymisation Groundhog Day

    Theresa Stadler, Bristena Oprisanu, and Carmela Troncoso. Synthetic Data – Anonymisation Groundhog Day. In 31st USENIX Security Symposium (USENIX Security 22), pages 1451–1468, Massachusetts, USA, 2022

  87. [95]

    Adversarial Attacks Against Deep Generative Models on Data: A Survey

    Hui Sun, Tianqing Zhu, Zhiqiu Zhang, Dawei Jin, Ping Xiong, and Wanlei Zhou. Adversarial Attacks Against Deep Generative Models on Data: A Survey. IEEE Transactions on Knowledge and Data Engineering , 35(4):3367–3388, April 2023

  88. [96]

    P3GM: Private High-Dimensional Data Release via Privacy Preserving Phased Generative Model

    Shun Takagi, Tsubasa Takahashi, Yang Cao, and Masatoshi Yoshikawa. P3GM: Private High-Dimensional Data Release via Privacy Preserving Phased Generative Model. In 2021 IEEE 37th International Conference on Data Engineering (ICDE), pages 169–180, Chania, Greece, April 2021. IEEE

  89. [97]

    Differ- entially Private Synthetic Mixed-Type Data Generation For Unsupervised Learning

    Uthaipon Tao Tantipongpipat, Chris Waites, Digvijay Boob, Amaresh Ankit Siva, and Rachel Cummings. Differ- entially Private Synthetic Mixed-Type Data Generation For Unsupervised Learning. In 2021 12th International Conference on Information, Intelligence, Systems & Application...

  90. [98]

    Fairness and privacy preservation for facial images: GAN-based methods

    Huan Tian, Tianqing Zhu, and Wanlei Zhou. Fairness and privacy preservation for facial images: GAN-based methods. Computers & Security, 122:102902, November 2022. 28

  91. [99]

    Fox, and Chandan K

    Amirsina Torfi, Edward A. Fox, and Chandan K. Reddy. Differentially private synthetic medical data generation using convolutional GANs. Information Sciences, 586:485–500, March 2022

  92. [100]

    DP-CGAN: Differentially Private Synthetic Data and Label Generation

    Reihaneh Torkzadehmahani, Peter Kairouz, and Benedict Paten. DP-CGAN: Differentially Private Synthetic Data and Label Generation. In 2019 IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), pages 98–104, Long Beach, CA, USA, June 2019. IEEE

  93. [101]

    Technical Privacy Metrics: A Systematic Survey

    Isabel Wagner and David Eckhoff. Technical Privacy Metrics: A Systematic Survey. ACM Computing Surveys, 51(3):1–38, May 2019

  94. [102]

    Generating Private Data Surrogates for Vision Related Tasks

    Ryan Webster, Julien Rabin, Loic Simon, and Frederic Jurie. Generating Private Data Surrogates for Vision Related Tasks. In 2020 25th International Conference on Pattern Recognition (ICPR), pages 263–269, Milan, Italy, January 2021. IEEE

  95. [103]

    IdentityDP: Differential private identification protection for face images

    Yunqian Wen, Bo Liu, Ming Ding, Rong Xie, and Li Song. IdentityDP: Differential private identification protection for face images. Neurocomputing, 501:197–211, August 2022

  96. [104]

    Visualizing Time Series Data with Temporal Matching Based t-SNE

    Kwan Yeung Wong and Fu-lai Chung. Visualizing Time Series Data with Temporal Matching Based t-SNE. In 2019 International Joint Conference on Neural Networks (IJCNN), pages 1–8, Budapest, Hungary, July 2019. ISSN: 2161-4407

  97. [105]

    Differentially Private Generative Adversarial Network, February 2018

    Liyang Xie, Kaixiang Lin, Shu Wang, Fei Wang, and Jiayu Zhou. Differentially Private Generative Adversarial Network, February 2018. arXiv:1802.06739 [cs, stat]

  98. [106]

    GANobfuscator: Mitigating Information Leakage Under GAN via Differential Privacy

    Chugui Xu, Ju Ren, Deyu Zhang, Yaoxue Zhang, Zhan Qin, and Kui Ren. GANobfuscator: Mitigating Information Leakage Under GAN via Differential Privacy. IEEE Transactions on Information Forensics and Security, 14(9):2358–2371, September 2019

  99. [107]

    FairGAN: Fairness-aware Generative Adversarial Networks

    Depeng Xu, Shuhan Yuan, Lu Zhang, and Xintao Wu. FairGAN: Fairness-aware Generative Adversarial Networks. In 2018 IEEE International Conference on Big Data (Big Data), pages 570–575, Seattle, Washington, USA, December 2018

  100. [108]

    Modeling tabular data using conditional gan

    Lei Xu, Maria Skoularidou, Alfredo Cuesta-Infante, and Kalyan Veeramachaneni. Modeling tabular data using conditional gan. Advances in Neural Information Processing Systems, 32:7335 – 7345, 2019

  101. [109]

    Andrew Yale, Saloni Dash, Ritik Dutta, Isabelle Guyon, Adrien Pavao, and Kristin P. Bennett. Generation and evaluation of privacy preserving synthetic health data. Neurocomputing, 416:244–255, November 2020

  102. [110]

    Differential Privacy Images Protection Based on Generative Adversarial Network

    Ren Yang, Xuebin Ma, Xiangyu Bai, and Xiangdong Su. Differential Privacy Images Protection Based on Generative Adversarial Network. In 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), pages 1688–1695, Guangzhou,...

  103. [111]

    Drumright, and Mihaela van der Schaar

    Jinsung Yoon, Lydia N. Drumright, and Mihaela van der Schaar. Anonymization Through Data Synthesis Using Generative Adversarial Networks (ADS-GAN). IEEE Journal of Biomedical and Health Informatics , 24(8):2378–2388, August 2020

  104. [112]

    Chenhan Zhang, Shui Yu, Zhiyi Tian, and James J. Q. Yu. Generative Adversarial Networks: A Survey on Attack and Defense Perspective. ACM Comput. Surv., 56(4):91:1–91:35, November 2023

  105. [113]

    Understanding Counterfactual Generation using Maximum Mean Discrepancy

    Wei Zhang, Brian Barr, and John Paisley. Understanding Counterfactual Generation using Maximum Mean Discrepancy. In Proceedings of the Third ACM International Conference on AI in Finance, ICAIF ’22, pages 44–52, New York, NY , USA, October 2022. Association for Computing Machinery

  106. [114]

    Boosting domain generalization by domain-aware knowledge distillation

    Zhongqiang Zhang, Ge Liu, Fuhan Cai, Duo Liu, and Xiangzhong Fang. Boosting domain generalization by domain-aware knowledge distillation. Knowledge-Based Systems, 280:111021, November 2023

  107. [115]

    Ziqi Zhang, Chao Yan, and Bradley A. Malin. Membership inference attacks against synthetic health data. Journal of Biomedical Informatics, 125:103977, January 2022

  108. [116]

    Zilong Zhao, Aditya Kunar, Robert Birke, Hiek Van der Scheer, and Lydia Y . Chen. CTAB-GAN+: enhancing tabular data synthesis. Frontiers in Big Data, 6, January 2024

  109. [117]

    Property Inference Attacks Against GANs

    Junhao Zhou, Yufei Chen, Chao Shen, and Yang Zhang. Property Inference Attacks Against GANs. In NDSS 2022, San Diego, California, April 2022

  110. [118]

    PKDGAN: Private Knowledge Distillation With Generative Adversarial Networks

    Cheng Zhuo, Di Gao, and Liangwei Liu. PKDGAN: Private Knowledge Distillation With Generative Adversarial Networks. IEEE Transactions on Big Data, pages 1–14, 2022. 29

  111. [2017]

    ISSN: 2640-3498

    PMLR. ISSN: 2640-3498

  112. [2018]

    arXiv:1812.05676 [cs, stat]

Pith tools

Reviewed August 9, 2026 · model on record in the stance chip above.